The application server and
database server requirements are of minimum configuration
Allows application security
of users logging in to the application that includes features
such as password encryption
Allows configurable password
controls in the application such as minimum length, character
set, mixed case, reuse restriction
Verification and validation
of data received from all external data sources
Maintains logs, security-related
events in the application (such as sessions established,
failed logon attempts, changes to security data and administrator
actions)